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AMENDMENTS TO THE CLAIMS: 

This listing of claims will replace all prior versions, and listings, of claims in the 
application: 

1. (original) A system for processing a computer file to determine whether it 
contains a virus or other malware comprising: 

means for generating data with regard to the file to characterise its identity and for 
thereby referencing a computer database to determine whether it is an instance of a 
known file; 

means for selectively subjecting the file to a number of heuristic procedures to 
determine whether or not it contains, or is likely to contain, malware; and 

means for determining, in dependence upon the record, if any, of the file in the 
database, whether the file can be regarded as safe and for controlling the means b) such 
that the file, if the file is to be regarded as safe, is either subject to less thorough 
processing than if it were not so regarded or not subject to processing by the means b) at 
all. 

2. (original) A system according to claim 1 wherein the controlling means c) 
controls the means b) in dependence on factors including the length of time for which the 
database indicates that the file has been known without malware-containing instances of 
it being detected. 
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3. (currently amended) A system according to claim wherein the 
controlling means c) controls the means b) in dependence on factors including sources, 
recorded in the database, from which instances of the file have originated. 

4. (currently amended) A system according to claim 1 , 2 or 3 wherein the 
controlling means c) controls the means b) in dependence on factors including the 
number of times, recorded in the database, of instances of the file have been processed. 

5. (currently amended) A system according to any one of the preceding 
claims claim 1 and including means for updating the database in dependence upon the 
result of the processing of the file by the means b). 

6. (original) A system according to claim 5 wherein the updating of the database, 
in the event of the means b) determining that the file contains, or is likely to contain, 
malware is such that the record thereof in the database is deleted, or updated so that it is 
no longer taken be safe. 

7. (original) A method of processing a computer file to determine whether it 
contains a virus or other malware comprising: 

generating data with regard to the file to characterise its identity and for thereby 
referencing a computer database to determine whether it is an instance of a known file; 
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selectively subjecting the file to a number of heuristic procedures to determine 
whether or not it contains, or is likely to contain, malware; and 

determining, in dependence upon the record, if any, of the file in the database, 
whether the file can be regarded as safe and conducting the step b) such that the file, if 
the file is to be regarded as safe, is either subject to less thorough processing than if it 
were not so regarded or not subject to processing by the step b) at all. 

8. (original) A method according to claim 7 wherein the determining step c) 
controls the step b) in dependence on factors including the length of time for which the 
database indicates that the file has been known without malware-containing instances of 
it being detected. 

9. (currently amended) A method according to claim 7 ef^8-wherein the 
determining step c) controls the step b) in dependence on factors including sources, 
recorded in the database, from which instances of the file have originated. 

10. (currently amended) A method according to claim 7 , 8 or 10 wherein the 
determining step c) controls the step b) in dependence on factors including the number of 
times, recorded in the database, instances of the file have been processed. 
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1 1 .(currently amended) A method according to any one claims 7 to lO claim 7 
and including the step of updating the database in dependence upon the result of the 
processing of the file by the step b). 

12.(original) A method according to claim 11 wherein the updating of the 
database, in the event of the step b) determining that the file contains, or is likely to 
contain, malware is such that the record thereof in the database is deleted, or updated so 
that it is no longer taken be safe. 
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